无法用360安全卫士删除sysspsyssp是木马吗,

360安全卫士:警惕木马伪装《我的少女时代》看片播放器
木马用热门影片伪装已经是老套路了,不幸的是仍然会有人上钩,而木马也不厌其烦地化身一部又一部热门片子来设下陷阱。据360安全卫士官方微博发布,以最近比较火的&我的少女时代&为例,木马是这样传播的:在百度贴吧发帖=&留一个在线看片地址=&提示下载&免缓冲播放器&。而所谓的播放器是根本看不了片子的,一旦装上就会有一大波流氓软件席卷电脑。提示下载免缓冲播放器影音,其实是一个没有播放能力的流氓软件推广器:比较搞笑的是,这个恶意程序的下载地址是-&&,以前我们见惯了木马在域名、函数中痛骂360的各种污言秽语,说&360么么哒&的还真是新鲜,而这个样本使用的其它两个域名也挺奇葩的,分别是:难道是木马被360穷追猛打之后有点神经错乱、卖萌示好?不管它,照杀不误!经过分析,这个恶意程序会使用新浪提供的地址服务来判断用户所在地区,避开安全软件公司以及北上广地区进行推广http://int..cn/iplookup/iplookup.php?format=json当判断这个地区可以进行推广后,会去下载一个加密的推广列表,域名为:(还来这套)好了继续&现在已经出现安装界面了,此时可以看到与在线播放没有任何关系,是个名为EyeGuard的推广程序,和播放器没有一毛钱关系。对于没有安全软件保护的网友来说,当双击这个&播放器&后,就已经无法阻止其安装了,因为这时你点击X去关闭软件会弹出如下界面.我想大家如果不是特别警惕,一般都会去点确定,然后会看到再往下的界面当你看到下图这个界面的时候,已经晚了。因为此时你再去点击X关闭这个软件,他会貌似退出,但实际上已经强制在后台静默安装这些推广程序了目前的推广列表如下话说这批木马使用的域名倒是让人非常感动啊&但是抱歉,我们是不可能的假视频网站:360安全卫士官方微博建议说,大家打开某些视频网站的时候,如果发现需要安装播放器,请搜索需要安装的播放器的名字找到官网下载安装,不要随意从视频网站点击下载播放器。如果网站没有说明需要的播放器的名字,请关闭该网站,顺手还可以点一下地址栏前面的图标,在弹出的窗口里面点击&举报该网站&,帮助我们更快地发现和拦截恶意网址。
软件论坛帖子排行
最新资讯离线随时看
聊天吐槽赢奖品
相关软件:
大小:42.5 MB
授权:免费
大小:33.23 MB
授权:免费查看: 2345|回复: 9
急求各位高手帮忙解决!!
arthor_pan
急求各位高手帮忙解决!!
各位高手:小弟的电脑只要一连接网络,za就会提醒有阻断间谍网址
同时卡巴会提醒
恶意 HTTP 对象 &&: 拒绝访问.
恶意 HTTP 对象 &&: 拒绝访问.
恶意 HTTP 对象 &&: 拒绝访问.
恶意 HTTP 对象 &&: 拒绝访问.
恶意 HTTP 对象 &&: 拒绝访问.
恶意 HTTP 对象 &&: 拒绝访问.
恶意 HTTP 对象 &&: 已检测 广告程序 not-a-
virus:AdWare.Win32.BHO.cx.
恶意 HTTP 对象 &&: 已检测 木马程序 Trojan-
Downloader.Win32.Small.ewc
恶意 HTTP 对象 &&: 已检测 木马程序 Trojan-
Downloader.Win32.Agent.awz.
不知如何处理这个问题,请高手指教,感谢!!
该诊断报告由360安全卫士提供
诊断时间: &&07:48:40
诊断平台: Microsoft Windows XP&&Service Pack 2
IE版本: Internet Explorer V6.0. Build:
计算机物理内存:767.53MB - 当前可用内存:487.14MB
100 - 未知 - Process: zlclient.exe [Zone Labs Client] -
R0 - 未知 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=/
O8 - 未知 - Extra context menu item: &使用BitComet下载 - res://C:\Program
Files\BitComet\BitComet.exe/AddLink.htm
O8 - 未知 - Extra context menu item: &使用BitComet下载全部链接 - res://C:\Program
Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - 未知 - Extra context menu item: &使用BitComet下载本页视频 - res://C:\Program
Files\BitComet\BitComet.exe/AddVideo.htm
O20 - 未知 - AppInit DLLs: jzgpri.dll
O23 - 未知 - Service: 469B2DE2 [78BA7F2C] -&&- (not running)
O23 - 未知 - Service: 9EA3BC2F [9EA3BC2F] -&&- (not running)
O23 - 未知 - Service: vsmon [Monitors internet traffic and generates alerts for disallowed access.] -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service - (running)
=======================================
100 - 安全 - Process: smss.exe [进程为会话管理子系统用以初始化系统变量,ms-dos驱动名称类似lpt1以及com,调
用win32壳子系统和运行在windows登陆过程。] - C:\windows\System32\smss.exe
100 - 安全 - Process: csrss.exe [客户端服务子系统,用以控制windows图形相关子系统。] -
C:\windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=2 Windows=On
SubSystemType=Windows ServerDll=base
100 - 安全 - Process: winlogon.exe [windows nt用户登陆程序。] - C:\windows\system32\winlogon.exe
100 - 安全 - Process: services.exe [用于管理windows服务系统进程。] - C:\windows\system32\services.exe
100 - 安全 - Process: lsass.exe [本地安全权限服务控制windows安全机制。] - C:\windows\system32\lsass.exe
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] -
C:\windows\system32\svchost -k DcomLaunch
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] -
C:\windows\system32\svchost -k rpcss
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] -
C:\windows\System32\svchost.exe -k netsvcs
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] -
C:\windows\system32\svchost.exe -k NetworkService
100 - 安全 - Process: svchost.exe [service host process是一个标准的动态连接库主机处理服务。] -
C:\windows\system32\svchost.exe -k LocalService
100 - 安全 - Process: vsmon.exe [一款个人防火墙软件。] -
100 - 安全 - Process: explorer.exe [windows program manager或者windows explorer用于控制windows图形shell,
包括开始菜单、任务栏,桌面和文件管理。] - C:\windows\Explorer.EXE
100 - 安全 - Process: spoolsv.exe [windows打印任务控制程序,用以打印机就绪。] - C:\windows\system32
\spoolsv.exe
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] -
100 - 安全 - Process: nvsvc32.exe [nvidia driver helper service在nvida显卡驱动中被安装。] -
C:\windows\system32\nvsvc32.exe
100 - 安全 - Process: SMAgent.exe [一个声卡相关软件。] - C:\Program Files\Analog
Devices\SoundMAX\SMAgent.exe
100 - 安全 - Process: wdfmgr.exe [windows media player播放器相关程序。] - C:\WINDOWS\system32\wdfmgr.exe
100 - 安全 - Process: alg.exe [这是一个应用层网关服务用于网络共享。] - C:\windows\System32\alg.exe
100 - 安全 - Process: htpatch.exe [矽统科技相关软件。] - C:\WINDOWS\htpatch.exe
100 - 安全 - Process: SMTray.exe [一个声卡相关软件。] - C:\Program Files\Analog
Devices\SoundMAX\SMTray.exe
100 - 安全 - Process: avp.exe [卡巴斯基杀毒软件相关程序。] -
100 - 安全 - Process: ctfmon.exe [office xp输入法图标。] - C:\windows\system32\ctfmon.exe
100 - 安全 - Process: VnetClient.exe [vnet虚拟拨号软件,用于adsl宽带拨号。] - C:\Program
Files\ChinaNet\VnetClient.exe
100 - 安全 - Process: IEXPLORE.EXE [microsoft internet explorer浏览器用于浏览网页。] - C:\Program
Files\Internet Explorer\iexplore.exe
100 - 安全 - Process: taskmgr.exe [windows自带的任务管理器程序,用于察看系统中的进程信息。] -
C:\windows\system32\taskmgr.exe
100 - 安全 - Process: 360Safe.exe [360安全卫士相关程序。] - C:\Program Files\360safe\360Safe.exe
100 - 安全 - Process: IEXPLORE.EXE [microsoft internet explorer浏览器用于浏览网页。] - C:\Program
Files\Internet Explorer\iexplore.exe
R1 - 安全 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\windows\system32\blank.htm
O2 - 安全 - BHO: (AcroIEHlprObj Class) - [Adobe Reader, 查看和打印 Adobe 便携文档格式 (PDF) 文件。] -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0
\Reader\ActiveX\AcroIEHelper.dll
O2 - 安全 - BHO: (BitComet Helper) - [下载软件BitComet的相关程序。] - {39F7E362-828A-4B5A-BCAF-
5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll
O2 - 安全 - BHO: (VnetCookie Class) - [星空极速, 拨号软件。] - {4E83D567-B-B1F0-A513B01DB89A} -
c:\PROGRA~1\chinanet\VNETTR~1.DLL
O2 - 安全 - BHO: (Thunder Browser Helper) - [迅雷附带下载监视器相关文件。] - {889D2FEB-98-
1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_001.dll
O4 - 安全 - HKLM\..\Run: [IMJPMIG8.1] [微软Microsoft输入法编辑器程序。] &C:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE& /Spoil /RemAdvDef /Migration32
O4 - 安全 - HKLM\..\Run: [PHIME2002ASync] [输入法软件相关程序。] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - 安全 - HKLM\..\Run: [PHIME2002A] [输入法软件相关程序。] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - 安全 - HKLM\..\Run: [HTpatch] [sis芯片主板的agp补丁。] C:\WINDOWS\htpatch.exe
O4 - 默认 - HKLM\..\Run: [Smapp] [analog device公司推出的soundmax的音频控制程序] C:\Program Files\Analog
Devices\SoundMAX\SMTray.exe
O4 - 安全 - HKLM\..\Run: [NvCplDaemon] [是NVIDIA显示卡相关动态链接库文件。] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - 安全 - HKLM\..\Run: [nwiz] [是NVidia的Nview特性相关程序。该程序用于用户对其特性进行配置,将桌面扩展
到多台显示器上。 ] nwiz.exe /install
O4 - 安全 - HKLM\..\Run: [kav] [卡巴斯基杀毒软件相关程序。] &C:\Program Files\Kaspersky Lab\Kaspersky
Anti-Virus 6.0\avp.exe&
O4 - 安全 - HKLM\..\Run: [Zone Labs Client] [zonelabs公司出品的个人防火墙软件。] &C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe&
O4 - 安全 - HKCU\..\Run: [ctfmon.exe] [office xp输入法图标。] C:\windows\system32\ctfmon.exe
O8 - 安全 - Extra context menu item: &使用迅雷下载 - C:\Program Files\Thunder
Network\Thunder\Program\GetUrl.htm
O8 - 安全 - Extra context menu item: &使用迅雷下载全部链接 - C:\Program Files\Thunder
Network\Thunder\Program\GetAllUrl.htm
O9 - 安全 - Extra button: 卡巴斯基Web反病毒保护插件(HKLM) - C:\Program Files\Kaspersky Lab\Kaspersky
Anti-Virus 6.0\scieplugin.dll
O9 - 安全 - Extra button: Windows Messenger(HKLM) - C:\Program Files\Messenger\msmsgs.exe
O23 - 安全 - Service: AVP [卡巴斯基杀毒软件相关程序。] - &C:\Program Files\Kaspersky Lab\Kaspersky Anti-
Virus 6.0\avp.exe& -r - (running)
O23 - 安全 - Service: NVSvc [是NVIDIA显示卡相关程序。] - C:\windows\system32\nvsvc32.exe - (running)
O23 - 安全 - Service: SoundMAX Agent Service (default) [是Analog SoundMAX声卡产品相关程序。] - C:\Program
Files\Analog Devices\SoundMAX\SMAgent.exe - (running)
=======================================
404 Not Found
404 Not Found
arthor_pan
O31 - 未知 - Notify: crypt32chain - C:\windows\system32\crypt32.dll - Microsoft Corporation - Crypto
API32 - 5.131. - 590336 - 6e818bd12c8bfd0a4155
O31 - 未知 - Notify: cryptnet - C:\windows\system32\cryptnet.dll - Microsoft Corporation - Crypto Network
Related API - 5.131. - 63488 - c288e0360ff43aac8d51cc5e4e85d783
O31 - 未知 - Notify: cscdll - C:\windows\system32\cscdll.dll - Microsoft Corporation - Offline Network
Agent - 5.1. - 99840 - bf80bcb0f8d260a170c31c
O31 - 未知 - Notify: klogon - C:\WINDOWS\system32\klogon.dll - Kaspersky Lab - Logon Visualizer -
6.0.0.299 - 28778 - c0f0cd54b48f
O31 - 未知 - Notify: ScCertProp - C:\windows\system32\wlnotify.dll - Microsoft Corporation - Common DLL
to receive Winlogon notifications - 5.1. - 89088 - 7c3b85b65d099a8bfec13
O31 - 未知 - Notify: Schedule - C:\windows\system32\wlnotify.dll - Microsoft Corporation - Common DLL to
receive Winlogon notifications - 5.1. - 89088 - 7c3b85b65d099a8bfec13
O31 - 未知 - Notify: sclgntfy - C:\windows\system32\sclgntfy.dll - Microsoft Corporation - Secondary
Logon Service Notification DLL - 5.1. - 18944 - 892f92ac9f27efe553aa5b
O31 - 未知 - Notify: SensLogn - C:\windows\system32\WlNotify.dll - Microsoft Corporation - Common DLL to
receive Winlogon notifications - 5.1. - 89088 - 7c3b85b65d099a8bfec13
O31 - 未知 - Notify: termsrv - C:\windows\system32\wlnotify.dll - Microsoft Corporation - Common DLL to
receive Winlogon notifications - 5.1. - 89088 - 7c3b85b65d099a8bfec13
O31 - 未知 - Notify: wlballoon - C:\windows\system32\wlnotify.dll - Microsoft Corporation - Common DLL to
receive Winlogon notifications - 5.1. - 89088 - 7c3b85b65d099a8bfec13
O31 - 未知 - SODL: {ea-486e-9f31a9} - C:\windows\system32\SHELL32.dll - Microsoft
Corporation - Windows Shell Common Dll - 6.0. - 8241664 -
O31 - 未知 - SODL: {fbeb8a05-beee-9d6c4515e9} - C:\windows\system32\SHELL32.dll - Microsoft
Corporation - Windows Shell Common Dll - 6.0. - 8241664 -
O31 - 未知 - SODL: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll - Microsoft
Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SODL: {35CEC8A3-2BE6-11D2-524153} - C:\WINDOWS\system32\stobject.dll - Microsoft
Corporation - Systray shell service object - 5.1. - 121344 - d2fd7bef2128
O31 - 未知 - SEApproved: {0-} - C:\windows\system32\mmsys.cpl -
Microsoft Corporation - Control Panel Drivers Applet - 5.1. - 600064 -
9fbd35431fefc
O31 - 未知 - SEApproved: {176d-11d1-b350-b03} - C:\windows\system32\icmui.dll -
Microsoft Corporation - Microsoft Color Matching System User Interface DLL - 5.1.2600.0 - 54784 -
25ee3108e8
O31 - 未知 - SEApproved: {1F2E5C40-9550-11CE-99D2-00AA006E086C} - C:\windows\system32\rshx32.dll -
Microsoft Corporation - Security Shell Extension - 5.1. - 37888 -
8a55ff4a4eb5fb807b55
O31 - 未知 - SEApproved: {3EA-101B-84FB-666CCB9BCD32} - C:\windows\system32\docprop.dll -
Microsoft Corporation - OLE DocFile Property Page - 5.1.2600.0 - 46080 - b6f75dd82f6ae648f4199
O31 - 未知 - SEApproved: {40dd6e20-7c17-11ce-a804-00aa003ca9f6} - C:\windows\system32\ntshrui.dll -
Microsoft Corporation - Shell extensions for sharing - 5.1. - 137216 -
O31 - 未知 - SEApproved: {41E300E0-78B6-11ce-849B-} - C:\windows\system32\themeui.dll -
Microsoft Corporation - Windows Theme API - 6.0. - 371200 - de87ebea462c15adede02434
O31 - 未知 - SEApproved: {d4-11d1-8b24-00a0c9068ff3} - C:\windows\system32\deskadp.dll -
Microsoft Corporation - Advanced display adapter properties - 6.0.2600.0 - 16384 -
2df0148bcdf1a691e47ae5fe7a3220c0
O31 - 未知 - SEApproved: {d4-11d1-8b24-00a0c9068ff3} - C:\windows\system32\deskmon.dll -
Microsoft Corporation - Advanced display monitor properties - 6.0.2600.0 - 16896 -
O31 - 未知 - SEApproved: {d4-11d1-8b24-00a0c9068ff3} - deskpan.dll -&&-&&-&&- 0 -
O31 - 未知 - SEApproved: {4E40F770-369C-11d0-AB2DBB} - C:\windows\system32\dssec.dll -
Microsoft Corporation - Directory Service Security UI - 5.1. - 48640 -
fdc0d5a2b9f1f7
O31 - 未知 - SEApproved: {513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} - C:\windows\system32\SlayerXP.dll -
Microsoft Corporation - Compatibility Tab Shell Extension DLL - 5.1. - 24576 -
d41aab80ae46d
O31 - 未知 - SEApproved: {CD-101B-81E2-00AA004AE837} - C:\windows\system32\shscrap.dll -
Microsoft Corporation - Shell scrap object handler - 5.1. - 25600 -
7a1db136abb94d5d6fdadd
O31 - 未知 - SEApproved: {FF-11CE-BD94-} - C:\windows\system32\diskcopy.dll -
Microsoft Corporation - Windows DiskCopy - 6.0.2600.0 - 1501696 - dd9a5ae9be30f
O31 - 未知 - SEApproved: {59bece-aff7-00aa003ca9f6} - C:\windows\system32\ntlanui2.dll -
Microsoft Corporation - Network object shell UI - 5.1.2600.0 - 14336 - 36feaeb48bd118eb82d6
O31 - 未知 - SEApproved: {5DB2625A-54DF-11D0-B6C4-5} - C:\windows\System32\icmui.dll -
Microsoft Corporation - Microsoft Color Matching System User Interface DLL - 5.1.2600.0 - 54784 -
25ee3108e8
O31 - 未知 - SEApproved: {675F097E-4C4D-11D0-B6C1-5} - C:\windows\system32\icmui.dll -
Microsoft Corporation - Microsoft Color Matching System User Interface DLL - 5.1.2600.0 - 54784 -
25ee3108e8
O31 - 未知 - SEApproved: 无效的CLSID:Shell extensions for file compression -&&-&&-&&-&&- 0 -
O31 - 未知 - SEApproved: {b15-11d0-a0c2-f03} - C:\windows\system32\printui.dll -
Microsoft Corporation - Print UI DLL - 5.1. - 524288 - 498b3eccadf9bdc1dedbcd
O31 - 未知 - SEApproved: {-EC89-11cf-9C00-00AA00A14F56} - C:\windows\system32\dskquoui.dll -
Microsoft Corporation - Windows Shell Disk Quota UI DLL - 5.1.2600.0 - 144384 -
43c63e2827663aca2d8af934fa2e8b19
O31 - 未知 - SEApproved: 无效的CLSID:加密上下文菜单 -&&-&&-&&-&&- 0 -
O31 - 未知 - SEApproved: {85BBD920-42A0--D} - C:\windows\system32\syncui.dll -
Microsoft Corporation - Windows Briefcase - 5.1. - 177152 - ba9145cfd1be57dc715e33
O31 - 未知 - SEApproved: {AA2-AA0030EBC8} - C:\WINDOWS\system32\hticons.dll -
Hilgraeve, Inc. - HyperTerminal Applet Library - 5.1.2600.0 - 44544 - 455e63cc325be7a6dbcc9
O31 - 未知 - SEApproved: {BD84B380-8CA2-1069-AB1D-} - C:\windows\system32\fontext.dll -
Microsoft Corporation - Windows Font Folder - 5.1. - 375808 - a17cc4f4e6e37c097e6e96d
O31 - 未知 - SEApproved: {DBCE1B-BE72-BA78E9AD5B27} - C:\windows\system32\icmui.dll -
Microsoft Corporation - Microsoft Color Matching System User Interface DLL - 5.1.2600.0 - 54784 -
25ee3108e8
O31 - 未知 - SEApproved: {F37CF-11d0-B4BF-00AA00BBB723} - C:\windows\system32\rshx32.dll -
Microsoft Corporation - Security Shell Extension - 5.1. - 37888 -
8a55ff4a4eb5fb807b55
O31 - 未知 - SEApproved: {f81e-11ce-a7ff-00aa003ca9f6} - C:\windows\system32\ntshrui.dll -
Microsoft Corporation - Shell extensions for sharing - 5.1. - 137216 -
O31 - 未知 - SEApproved: {f92e8c40-3d33-11d2-b1aa-b03} - C:\windows\system32\deskperf.dll -
Microsoft Corporation - Advanced display performance properties - 5.1.2600.0 - 18432 -
82f4dd2113aff745c63abdba3ecf2c56
O31 - 未知 - SEApproved: {BF-11D1-8CD9-00C04FC29D45} - C:\WINDOWS\system32\cryptext.dll -
Microsoft Corporation - Crypto Shell Extensions - 5.131. - 52736 -
13d12db2bcba
O31 - 未知 - SEApproved: {BF-11D1-8CD9-00C04FC29D45} - C:\WINDOWS\system32\cryptext.dll -
Microsoft Corporation - Crypto Shell Extensions - 5.131. - 52736 -
13d12db2bcba
O31 - 未知 - SEApproved: {7007ACC7--AAD2-0E} - C:\WINDOWS\system32\NETSHELL.dll -
Microsoft Corporation - Network Connections Shell - 5.1. - 1655808 -
32e0dd36b48a5117dfa9
O31 - 未知 - SEApproved: {992CFFA0-F557-101A-88EC-00DD010CCC48} - C:\WINDOWS\system32\NETSHELL.dll -
Microsoft Corporation - Network Connections Shell - 5.1. - 1655808 -
32e0dd36b48a5117dfa9
O31 - 未知 - SEApproved: {E211B736-43FD-11D1-9EFB-FCD} - C:\windows\system32\wiashext.dll -
Microsoft Corporation - Imaging Devices Shell Folder UI - 5.1. - 579072 -
974fd9f48f26dd9fffa0afb
O31 - 未知 - SEApproved: {FB0C9C8A-6C50-11D1-9F1D-FCD} - C:\windows\system32\wiashext.dll -
Microsoft Corporation - Imaging Devices Shell Folder UI - 5.1. - 579072 -
974fd9f48f26dd9fffa0afb
O31 - 未知 - SEApproved: {905667aa-acd6-11d2-f6596d2} - C:\windows\system32\wiashext.dll -
Microsoft Corporation - Imaging Devices Shell Folder UI - 5.1. - 579072 -
974fd9f48f26dd9fffa0afb
O31 - 未知 - SEApproved: {3F8-4f6e-A73A-04AAC7A992F1} - C:\windows\system32\wiashext.dll -
Microsoft Corporation - Imaging Devices Shell Folder UI - 5.1. - 579072 -
974fd9f48f26dd9fffa0afb
O31 - 未知 - SEApproved: {83bbcbf3-b28a-4919-a5aa-} - C:\windows\system32\wiashext.dll -
Microsoft Corporation - Imaging Devices Shell Folder UI - 5.1. - 579072 -
974fd9f48f26dd9fffa0afb
O31 - 未知 - SEApproved: {FE-FC} - C:\WINDOWS\system32\remotepg.dll -
Microsoft Corporation - Remote Sessions CPL Extension - 5.1. - 57344 -
aa7ac886119e
O31 - 未知 - SEApproved: {6B-11CF-8C96-00AA00B8708C} - C:\WINDOWS\system32\wshext.dll -
Microsoft Corporation - Microsoft (r) Shell Extension for Windows Script Host - 5.6.0.8820 - 65536 -
abdcc5ead54e6805731af
O31 - 未知 - SEApproved: {2206CDB2-19C1-11D1-89E0-00C04FD7A829} - C:\Program Files\Common
Files\System\Ole DB\oledb32.dll - Microsoft Corporation - Microsoft Data Access - OLE DB Core Services -
2.81.1117.0 - 487424 - c2f52f82d0
O31 - 未知 - SEApproved: {DDEEF-11cf-8D8E-00AA0060F5BF} - C:\WINDOWS\system32\mstask.dll -
Microsoft Corporation - Task Scheduler interface DLL - 5.1. - 260608 -
a3c34b78cfef5c4ef5382
O31 - 未知 - SEApproved: {797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} - C:\WINDOWS\system32\mstask.dll -
Microsoft Corporation - Task Scheduler interface DLL - 5.1. - 260608 -
a3c34b78cfef5c4ef5382
O31 - 未知 - SEApproved: {DC6A-11CF-8D87-00AA0060F5BF} - C:\WINDOWS\system32\mstask.dll -
Microsoft Corporation - Task Scheduler interface DLL - 5.1. - 260608 -
a3c34b78cfef5c4ef5382
O31 - 未知 - SEApproved: {-21d7-11d4-bdaf-00c04f60b9f0} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {0DF44EAA-FF21-0A} -&&-&&-&&-&&- 0 -
O31 - 未知 - SEApproved: {-21d7-11d4-bdaf-00c04f60b9f0} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {-21d7-11d4-bdaf-00c04f60b9f0} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {-21d7-11d4-bdaf-00c04f60b9f0} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {-21d7-11d4-bdaf-00c04f60b9f0} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {-21d7-11d4-bdaf-00c04f60b9f0} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {-21d7-11d4-bdaf-00c04f60b9f0} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {D20EA4E1--A40B-0C} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {D20EA4E1--A40B-0C} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {596AB062-B4D2--E3} - C:\windows\system32\twext.dll -
Microsoft Corporation - Previous Versions property page - 6.0. - 44032 -
27f34caa2e4c5f55931d
O31 - 未知 - SEApproved: {9DB7A13C-F208-CC61AE2783} - C:\windows\system32\twext.dll -
Microsoft Corporation - Previous Versions property page - 6.0. - 44032 -
27f34caa2e4c5f55931d
O31 - 未知 - SEApproved: {875CB1A1-0F29-45de-A1AE-CFB} - C:\windows\system32\shmedia.dll -
Microsoft Corporation - Media File Property Extractor Shell Extension - 6.0. - 147968 -
0c5f6e6b6ffd3b57ca8ae4
O31 - 未知 - SEApproved: {40C3D757-D6E4-4b49-BB41-0E5BBEA28817} - C:\windows\system32\shmedia.dll -
Microsoft Corporation - Media File Property Extractor Shell Extension - 6.0. - 147968 -
0c5f6e6b6ffd3b57ca8ae4
O31 - 未知 - SEApproved: {E4B29F9D-D390-480b-92FD-7DDB47101D71} - C:\windows\system32\shmedia.dll -
Microsoft Corporation - Media File Property Extractor Shell Extension - 6.0. - 147968 -
0c5f6e6b6ffd3b57ca8ae4
O31 - 未知 - SEApproved: {87D62D94-71B3-4b9a-50DC73E} - C:\windows\system32\shmedia.dll -
Microsoft Corporation - Media File Property Extractor Shell Extension - 6.0. - 147968 -
0c5f6e6b6ffd3b57ca8ae4
O31 - 未知 - SEApproved: {A6FD9E45-6E44-43f9-F5A74D9} - C:\windows\system32\shmedia.dll -
Microsoft Corporation - Media File Property Extractor Shell Extension - 6.0. - 147968 -
0c5f6e6b6ffd3b57ca8ae4
O31 - 未知 - SEApproved: {c5a40261-cd64-4ccf-84cb-c394da41d590} - C:\windows\system32\shmedia.dll -
Microsoft Corporation - Media File Property Extractor Shell Extension - 6.0. - 147968 -
0c5f6e6b6ffd3b57ca8ae4
O31 - 未知 - SEApproved: {5E6AB780-7743-11CF-A12B-00AA004AE837} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {22BF0C20-6DA7-11D0-B373-00A0C9034938} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {91EA3F8B-C99B-11d0-FD91972} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {6413BA2C-B461-11d1-A18A-A03} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {F61FFEC1-754F-11d0-80CA-00AA005B4383} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {7BA4C742-9E81-11CF-99D3-00AA004AE837} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {30D-11d0-FD5AE38} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {169A-11d1-A1C4-00C04FD75D13} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {-AF23-11d1-C98BA67D} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {AF4Fd0-4CD6D8} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {01E04581-4EEE-11d0-BFE9-00AA005B4383} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
arthor_pan
O31 - 未知 - SEApproved: {A08C11D2-A228-11d0-825B-00AA005B4383} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {00BB-11D0-A535-00C04FD7D062} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {3-11d0-A3A5-00C04FD706EC} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {-DE71-11d0-831B-00AA005B4383} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {E8-4ccc-BEB9-9FE3C77A297A} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {7e653215-fa25-46bd-a339-34a} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {acfe--becbe19f0ac9} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {00BB-11D0-A535-00C04FD7D062} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {03C036F1-A186-11D0-824A-00AA005B4383} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {00BB-11D0-A535-00C04FD7D062} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {ECD4FC4E-521C-11D0-B792-00A0C90312E1} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {3CCF8A41-5C85-11d0-B90ADF} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {ECD4FC4C-521C-11D0-B792-00A0C90312E1} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {ECD4FC4D-521C-11D0-B792-00A0C90312E1} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {DD313E04-FEFF-11d1-8ECD-C} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {EF8AD2D1-AE36-11D1-B2D2-C11} - C:\windows\system32\browseui.dll -
Microsoft Corporation - Shell Browser UI Library - 6.0. - 1016832 -
5e533ead07fd7eafef2179f
O31 - 未知 - SEApproved: {EFA24E61-B078-11d0-89E4-00C04FC9E26E} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {0A89A860-D7B1-11CE-40000} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {E7E4BC40-E76A-11CE-A9BB-00AA004AE837} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {A5E46E3A--9D8C-00C04FC99D61} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {FBF23B40-E3F0-101B-3E56F8} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {3C374A40-BAE4-11CF-BF7D-00AA006946EE} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {FFA7-11CF-BFF4-} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {7BD29E00-76C1-11CF-9DD0-00A0C9034933} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {7BD29E01-76C1-11CF-9DD0-00A0C9034933} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {67EA19A0-CCEF-11d0-FD75D13} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {131A-11D0-A979-00C04FD705A2} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {c5a-11d2-bf8b-00c04fb93661} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {3DC7A020-0ACD-11CF-A9BB-00AA004AE837} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {871C-1069-A2EA-D} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {EFA24E64-B078-11d0-89E4-00C04FC9E26E} - C:\windows\system32\shdocvw.dll -
Microsoft Corporation - Shell Doc Object and Control Library - 6.0. - 1482752 -
58ca1ae02a
O31 - 未知 - SEApproved: {9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} - C:\WINDOWS\system32\sendmail.dll -
Microsoft Corporation - Send Mail - 6.0. - 54272 - bec31e4ee3ab4ed079a95d
O31 - 未知 - SEApproved: {9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} - C:\WINDOWS\system32\sendmail.dll -
Microsoft Corporation - Send Mail - 6.0. - 54272 - bec31e4ee3ab4ed079a95d
O31 - 未知 - SEApproved: {88C6C381-2E85-11D0-94DE-} - C:\windows\system32\occache.dll -
Microsoft Corporation - Object Control Viewer - 6.0. - 93696 - 612c403e1e1c4c131e76f2eb1058ad0d
O31 - 未知 - SEApproved: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {F8-11d0-9C5E-00AA00A45957} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {06-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {7D559C10-9FE9-11d0-93F7-00AA0059CE02} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {E6CCE-11D0-BECA-00C04FD940BE} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {D8BD-11D0-864F-00AA} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} - C:\windows\system32\webcheck.dll -
Microsoft Corporation - Web Site Monitor - 6.0. - 265728 - 510fdc5d2c361e6212d50ffb
O31 - 未知 - SEApproved: {352EC2B7-8B9A-11D1-B8AE-} - C:\windows\system32\appwiz.cpl -
Microsoft Corporation - Shell Application Manager - 5.1. - 538112 -
e1f1246b14afdfe158aba1cbc180edf5
O31 - 未知 - SEApproved: {0B124F8F-91F0-11D1-B8B5-} - C:\windows\system32\appwiz.cpl -
Microsoft Corporation - Shell Application Manager - 5.1. - 538112 -
e1f1246b14afdfe158aba1cbc180edf5
O31 - 未知 - SEApproved: {CFCCC7A0-A282-11D1-59382} - C:\windows\system32\appwiz.cpl -
Microsoft Corporation - Shell Application Manager - 5.1. - 538112 -
e1f1246b14afdfe158aba1cbc180edf5
O31 - 未知 - SEApproved: {e84fda7c-1d6a-45f6-b725-cb260c236066} - C:\windows\system32\shimgvw.dll -
Microsoft Corporation - Windows 图片和传真查看器 - 6.0. - 434176 -
f821ff7fef803
O31 - 未知 - SEApproved: {66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} - C:\windows\system32\shimgvw.dll -
Microsoft Corporation - Windows 图片和传真查看器 - 6.0. - 434176 -
f821ff7fef803
O31 - 未知 - SEApproved: {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} -&&-&&-&&-&&- 0 -
O31 - 未知 - SEApproved: {3F30C968-480A-4C6C-862D-EFC0897BB84B} - C:\WINDOWS\system32\shimgvw.dll -
Microsoft Corporation - Windows 图片和传真查看器 - 6.0. - 434176 -
f821ff7fef803
O31 - 未知 - SEApproved: {9DBD2C50-62AD-11d0-B806-00C04FD706EC} - C:\WINDOWS\system32\shimgvw.dll -
Microsoft Corporation - Windows 图片和传真查看器 - 6.0. - 434176 -
f821ff7fef803
O31 - 未知 - SEApproved: {EAB841A0-9550-11cf-8C16-F3} - C:\WINDOWS\system32\shimgvw.dll -
Microsoft Corporation - Windows 图片和传真查看器 - 6.0. - 434176 -
f821ff7fef803
O31 - 未知 - SEApproved: {eb9b-4e68-959a-afe} - C:\windows\system32\shimgvw.dll -
Microsoft Corporation - Windows 图片和传真查看器 - 6.0. - 434176 -
f821ff7fef803
O31 - 未知 - SEApproved: {CC6EEFFB-43F6-46c5-967F7D} - C:\windows\system32\netplwiz.dll -
Microsoft Corporation - Map Network Drives/Network Places Wizard - 5.1. - 847360 -
6f40ede48d14
O31 - 未知 - SEApproved: {add36aa8-751a--d66f5202ccbb} - C:\windows\system32\netplwiz.dll -
Microsoft Corporation - Map Network Drives/Network Places Wizard - 5.1. - 847360 -
6f40ede48d14
O31 - 未知 - SEApproved: {6b3-4b6c-bf21-45de9cd503a1} - C:\windows\system32\netplwiz.dll -
Microsoft Corporation - Map Network Drives/Network Places Wizard - 5.1. - 847360 -
6f40ede48d14
O31 - 未知 - SEApproved: {58f1f272--b6d4-fd63d1618591} - C:\windows\system32\netplwiz.dll -
Microsoft Corporation - Map Network Drives/Network Places Wizard - 5.1. - 847360 -
6f40ede48d14
O31 - 未知 - SEApproved: {7A9D77BD--0524153} -&&-&&-&&-&&- 0 -
O31 - 未知 - SEApproved: {E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} - C:\windows\system32\zipfldr.dll -
Microsoft Corporation - Compressed (zipped) Folders - 6.0. - 328192 -
bc22aaebdf88c075f9494fbd8a8dbd48
O31 - 未知 - SEApproved: {BD472F60-27FA-11cf-B8B4-} - C:\windows\system32\zipfldr.dll -
Microsoft Corporation - Compressed (zipped) Folders - 6.0. - 328192 -
bc22aaebdf88c075f9494fbd8a8dbd48
O31 - 未知 - SEApproved: {888DCA60-FC0A-11CF-8F0F-00C04FD7D062} - C:\windows\system32\zipfldr.dll -
Microsoft Corporation - Compressed (zipped) Folders - 6.0. - 328192 -
bc22aaebdf88c075f9494fbd8a8dbd48
O31 - 未知 - SEApproved: {f39a0dc0-9cc8-11d0-a599-00c04fd64433} - C:\windows\system32\cdfview.dll -
Microsoft Corporation - Channel Definition File Viewer - 6.0. - 149504 -
a31f282b665d5b8dceade
O31 - 未知 - SEApproved: {f3aa0dc0-9cc8-11d0-a599-00c04fd64434} - C:\windows\system32\cdfview.dll -
Microsoft Corporation - Channel Definition File Viewer - 6.0. - 149504 -
a31f282b665d5b8dceade
O31 - 未知 - SEApproved: {f3ba0dc0-9cc8-11d0-a599-00c04fd64435} - C:\windows\system32\cdfview.dll -
Microsoft Corporation - Channel Definition File Viewer - 6.0. - 149504 -
a31f282b665d5b8dceade
O31 - 未知 - SEApproved: {f3da0dc0-9cc8-11d0-a599-00c04fd64437} - C:\windows\system32\cdfview.dll -
Microsoft Corporation - Channel Definition File Viewer - 6.0. - 149504 -
a31f282b665d5b8dceade
O31 - 未知 - SEApproved: {f3ea0dc0-9cc8-11d0-a599-00c04fd64438} - C:\windows\system32\cdfview.dll -
Microsoft Corporation - Channel Definition File Viewer - 6.0. - 149504 -
a31f282b665d5b8dceade
O31 - 未知 - SEApproved: {692F0339-CBAA-47e6-B5B5-3B84DB604E87} - C:\windows\system32\extmgr.dll -
Microsoft Corporation - Extensions Manager - 6.0. - 55808 - 252f969e160a7748f1eca923d39322ea
O31 - 未知 - SEApproved: {63da6ec0-2e98-11cf-8d82-} - C:\WINDOWS\system32\msieftp.dll -
Microsoft Corporation - Microsoft Internet Explorer FTP Folder Shell Extension - 6.0. - 240128 -
dc456a894b0e3f8f784030
O31 - 未知 - SEApproved: {-BF89-11D1-BE35-A03} - C:\WINDOWS\system32\docprop2.dll -
Microsoft Corporation - Microsoft DocProp Shell Ext - 5.1. - 47104 -
d8a09df5f5eb
O31 - 未知 - SEApproved: {A9CF0EAE-901A--E35B73E47F6D} - C:\WINDOWS\system32\docprop2.dll -
Microsoft Corporation - Microsoft DocProp Shell Ext - 5.1. - 47104 -
d8a09df5f5eb
O31 - 未知 - SEApproved: {8EE97210-FD1F-4B19-91DA-} - C:\WINDOWS\system32\docprop2.dll -
Microsoft Corporation - Microsoft DocProp Shell Ext - 5.1. - 47104 -
d8a09df5f5eb
O31 - 未知 - SEApproved: {0EEA25CC--850B-86EE61B0D3EB} - C:\WINDOWS\system32\docprop2.dll -
Microsoft Corporation - Microsoft DocProp Shell Ext - 5.1. - 47104 -
d8a09df5f5eb
O31 - 未知 - SEApproved: {6A205B57-C-B881-F787FAB579A3} - C:\WINDOWS\system32\docprop2.dll -
Microsoft Corporation - Microsoft DocProp Shell Ext - 5.1. - 47104 -
d8a09df5f5eb
O31 - 未知 - SEApproved: {28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} - C:\WINDOWS\system32\docprop2.dll -
Microsoft Corporation - Microsoft DocProp Shell Ext - 5.1. - 47104 -
d8a09df5f5eb
O31 - 未知 - SEApproved: {8A23E65E-31C2-11d0-891C-00A024AB2DBB} - C:\windows\system32\dsquery.dll -
Microsoft Corporation - Directory Service Find - 5.1. - 235520 -
60fa0d808d0
O31 - 未知 - SEApproved: {9E51E0D0-6E0F-11d2-FA31A86} - C:\windows\system32\dsquery.dll -
Microsoft Corporation - Directory Service Find - 5.1. - 235520 -
60fa0d808d0
O31 - 未知 - SEApproved: {163FDC20-2ABC-11d0-88F0-00A024AB2DBB} - C:\windows\system32\dsquery.dll -
Microsoft Corporation - Directory Service Find - 5.1. - 235520 -
60fa0d808d0
O31 - 未知 - SEApproved: {F020E586--A532-E} - C:\windows\system32\dsquery.dll -
Microsoft Corporation - Directory Service Find - 5.1. - 235520 -
60fa0d808d0
O31 - 未知 - SEApproved: {0D45D530-764B-11d0-A1CA-00AA00C16E65} - C:\windows\system32\dsuiext.dll -
Microsoft Corporation - Directory Service Common UI - 5.1. - 112128 -
6e520a18fdb7c99ab16d7993eaf42a6f
arthor_pan
O31 - 未知 - SEApproved: {ECF03A33-103D-11d2-854D-} - C:\windows\system32\mydocs.dll -
Microsoft Corporation - My Documents Folder UI - 6.0. - 88576 - d3efc4b7
O31 - 未知 - SEApproved: {ECF03A32-103D-11d2-854D-} - C:\windows\system32\mydocs.dll -
Microsoft Corporation - My Documents Folder UI - 6.0. - 88576 - d3efc4b7
O31 - 未知 - SEApproved: {4a7ded0a-ad25-11d0-98a8-3} - C:\windows\system32\mydocs.dll -
Microsoft Corporation - My Documents Folder UI - 6.0. - 88576 - d3efc4b7
O31 - 未知 - SEApproved: {750fdf0e-2a26-11d1-a3ea-} - C:\windows\System32\cscui.dll -
Microsoft Corporation - Client Side Caching UI - 5.1. - 304128 -
0aad9cbf94dc
O31 - 未知 - SEApproved: {10CFC467--8DB4-00C04FA31A66} - C:\windows\System32\cscui.dll -
Microsoft Corporation - Client Side Caching UI - 5.1. - 304128 -
0aad9cbf94dc
O31 - 未知 - SEApproved: {AFDB1F70-2A4C-11d2-F8EEB3E} - C:\windows\System32\cscui.dll -
Microsoft Corporation - Client Side Caching UI - 5.1. - 304128 -
0aad9cbf94dc
O31 - 未知 - SEApproved: {143A62C8-C33B-11D1-84FE-00C04FA34A14} - C:\WINDOWS\msagent\agentpsh.dll -
Microsoft Corporation - Microsoft Agent Property Sheet Handler - 2.0.0.3422 - 24064 -
8d1daab333fcac2e823b
O31 - 未知 - SEApproved: {ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} - C:\WINDOWS\system32\dfsshlex.dll -
Microsoft Corporation - Distributed File System shell extension - 5.1. - 28672 -
63b077bad8e8c3842643cfc6437dfa06
O31 - 未知 - SEApproved: {60fd46de-f830-fa81bc0190d} - C:\windows\system32\photowiz.dll -
Microsoft Corporation - Photo Printing Wizard - 5.1. - 167424 - ee978b86e0e0e1bf8e5e3a7f0d6658b2
O31 - 未知 - SEApproved: {7A80E4A8--BCF8-00C04F72C717} - C:\windows\System32\mmcshext.dll -
Microsoft Corporation - MMC Shell Extension DLL - 5.1. - 50688 -
bed3ca2f68ddaf21a74d21
O31 - 未知 - SEApproved: {0CD7A5C0-9F37-11CE-AE65-2} - C:\windows\system32\cabview.dll -
Microsoft Corporation - Cabinet File Viewer Shell Extension - 6.0. - 83456 -
ff407ffa4ddf7dcd83646b
O31 - 未知 - SEApproved: {E5F-11d0-8B85-00AA} - C:\Program Files\Outlook
Express\wabfind.dll - Microsoft Corporation - Find People - 6.0. - 32768 -
ac5bb39e99df96d54f4eb
O31 - 未知 - SEApproved: {8DD448E6-C188-4aed-AF92-F} - C:\WINDOWS\system32\wmpshell.dll -
Microsoft Corporation - Windows Media Player Launcher - 10.0.0.3802 - 86016 -
184e6b5cd477b0debe5c6b1
O31 - 未知 - SEApproved: {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} - C:\WINDOWS\system32\wmpshell.dll -
Microsoft Corporation - Windows Media Player Launcher - 10.0.0.3802 - 86016 -
184e6b5cd477b0debe5c6b1
O31 - 未知 - SEApproved: {F1B9284F-E9DC-4e68-9D7E-FD} - C:\WINDOWS\system32\wmpshell.dll -
Microsoft Corporation - Windows Media Player Launcher - 10.0.0.3802 - 86016 -
184e6b5cd477b0debe5c6b1
O31 - 未知 - SEApproved: {1CDB-3E7C208A5D} - C:\WINDOWS\system32\nvshell.dll -
NVIDIA Corporation - NVIDIA Desktop Explorer, Version 40.72&&- 6.13.10.4072 - 516167 -
a6ae30d17b13d
O31 - 未知 - SEApproved: {1E9B04FB-F9E5-B-B8DA88302A47} - C:\WINDOWS\system32\nvshell.dll -
NVIDIA Corporation - NVIDIA Desktop Explorer, Version 40.72&&- 6.13.10.4072 - 516167 -
a6ae30d17b13d
O31 - 未知 - SEApproved: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll -&&-
-&&- 120832 - c608a651ff649ba985af5
O31 - 未知 - SEApproved: {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - C:\Program Files\Kaspersky
Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll - Kaspersky Lab - Script Monitor Internet Explorer plugin -
6.0.0.299 - 184430 - 3f6db09f466b9e4fa21d6a5
O31 - 未知 - SEApproved: {-59b0-47a6-b335-a6b3c0695aea} - C:\windows\system32\Audiodev.dll -
Microsoft Corporation - 便携媒体设备命令行解释器扩展 - 5.2. - 484352 -
d56ea61a764ed7b13c4b30
O31 - 未知 - SEApproved: {cc86590a-b60a-48e6-996b-41d25ed39a1e} - C:\windows\system32\Audiodev.dll -
Microsoft Corporation - 便携媒体设备命令行解释器扩展 - 5.2. - 484352 -
d56ea61a764ed7b13c4b30
O31 - 未知 - Directory Menu: {A470F8CF-A1E8-4f65-AA5C46} - C:\windows\system32\SHELL32.dll -
Microsoft Corporation - Windows Shell Common Dll - 6.0. - 8241664 -
O31 - 未知 - Directory Menu: {750fdf0e-2a26-11d1-a3ea-} - C:\windows\System32\cscui.dll -
Microsoft Corporation - Client Side Caching UI - 5.1. - 304128 -
0aad9cbf94dc
O31 - 未知 - Directory Menu: {f81e-11ce-a7ff-00aa003ca9f6} - C:\windows\system32\ntshrui.dll -
Microsoft Corporation - Shell extensions for sharing - 5.1. - 137216 -
O31 - 未知 - Directory Menu: {B41DB860-8EE4-11D2-9906-E49FADC173CA} - C:\Program Files\WinRAR\rarext.dll
-&&-&&-&&- 120832 - c608a651ff649ba985af5
O31 - 未知 - LSA: Authentication Packages - C:\windows\system32\msv1_0.dll - Microsoft Corporation -
Microsoft Authentication Package v1.0 - 5.1. - 129536 - bb1fedab741fffff0a5354
O31 - 未知 - LSA: Notification Packages - C:\windows\system32\scecli.dll - Microsoft Corporation -
Windows Security Configuration Editor Client Engine - 5.1. - 171008 -
b1abbea399d
O31 - 未知 - LSA: Security Packages - C:\windows\system32\kerberos.dll - Microsoft Corporation - Kerberos
Security Package - 5.1. - 294400 - 0b035f9de7147ddab23c7
O31 - 未知 - LSA: Security Packages - sv1_0.dll -&&-&&-&&- 0 -
O31 - 未知 - LSA: Security Packages - channel.dll -&&-&&-&&- 0 -
O31 - 未知 - LSA: Security Packages - C:\windows\system32\digest.dll - Microsoft Corporation - Digest
SSPI Authentication Package - 6.0. - 68096 - abc2c0dcc02a9c33d6f127fe
=======================================
O40 - winlogon.exe -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - winlogon.exe - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - winlogon.exe - Kaspersky Lab - C:\WINDOWS\system32\klogon.dll - Logon Visualizer -
c0f0cd54b48f
O40 - winlogon.exe - Microsoft Corporation - C:\windows\system32\asycfilt.dll -&&-
d5dba4af017da0bca3dff
O40 - services.exe -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - services.exe - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - lsass.exe -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - lsass.exe - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - svchost.exe -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - svchost.exe - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - svchost.exe -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - svchost.exe - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - svchost.exe -&&- C:\windows\System32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - svchost.exe - SoundMAX - C:\windows\System32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - svchost.exe -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - svchost.exe - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - svchost.exe -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - svchost.exe - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - Explorer.EXE -&&- C:\windows\system32\jzgpri.dll -&&- dc6e3d1b2a7e874c4f8f96
O40 - Explorer.EXE - SoundMAX - C:\windows\system32\SYNCOR11.DLL - SynthCore R2.0 Midi Interface Driver -
bd9bacc0e08de9c
O40 - Explorer.EXE -&&- C:\windows\system32\xatc.dll -&&-
O40 - Explorer.EXE - Microsoft Corporation - C:\PROGRA~1\WINDOW~2\wmpband.dll - Windows Media Player -
afe426be3cc
O40 - Explorer.EXE - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll
- Windows Shell Extension - c81f4fba680
O40 - Explorer.EXE - Thunder Networking Technologies,LTD - C:\Program Files\Thunder
Network\Thunder\ComDlls\XunLeiBHO_001.dll - XunLeiBHO - 20feda3437be41aaa31db
O40 - Explorer.EXE - Microsoft Corporation - C:\windows\system32\shmedia.dll - Media File Property
Extractor Shell Extension - 0c5f6e6b6ffd3b57ca8ae4
O40 - Explorer.EXE - Microsoft Corporation - C:\windows\system32\MSVFW32.dll - Microsoft Video for
Windows DLL - effdec49653a
O40 - Explorer.EXE - Microsoft Corporation - C:\windows\system32\AVIFIL32.dll - Microsoft AVI File
support library - dd83188bcf94cee456a6ab
=======================================
O41 - aeaudio - Andrea Audio Stub Driver - C:\WINDOWS\system32\drivers\aeaudio.sys - (running) - Andrea
Audio Stub Driver - Andrea Electronics Corporation - 11c04b17ed2abbb4833694bcd644ac90
O41 - aq7r1jkju - aq7r1jkju - C:\WINDOWS\system32\drivers\aq7r1jkju.sys - (running) -&&-&&-
O41 - gameenum - Game Port Enumerator - C:\WINDOWS\system32\drivers\gameenum.sys - (running) - Game Port
Enumerator - Microsoft Corporation - 5f92fd09eda7d775eadcd12
O41 - hckba4r - hckba4r - C:\WINDOWS\system32\drivers\hckba4r.sys - (running) -&&-&&-
9c2b5ecd2f5fd344926b
O41 - kl1 - Kaspersky Unified Driver - C:\WINDOWS\system32\drivers\kl1.sys - (running) - Kaspersky
Unified Driver - Kaspersky Lab - dedf5f85b9daf712fdd09
O41 - klif - spuper-ptor - C:\WINDOWS\system32\drivers\klif.sys - (running) - spuper-ptor - Kaspersky Lab
- d06f997bb1819
O41 - npkcrypt - nProtect KeyCrypt Driver - C:\Program Files\Tencent\QQ\npkcrypt.sys - (running) -
nProtect KeyCrypt Driver - INCA Internet Co., Ltd. - 8bcb281a2540e7aff0cd00f9878fe21f
O41 - sisagp - SiS NT AGP Filter - C:\WINDOWS\system32\drivers\SISAGPX.SYS - (running) - SiS NT AGP
Filter - Silicon Integrated Systems Corporation - 1630fbdbcb0cf3a60c02b6f140bab98b
O41 - SiSide - SiS PCI Mini IDE Driver - C:\WINDOWS\system32\drivers\siside.sys - (running) - SiS PCI
Mini IDE Driver - Silicon Integrated Systems Corp. - 37ccc7eee3ea
O41 - sisidex - SISIDEX Driver - C:\WINDOWS\system32\drivers\sisidex.sys - (running) - SISIDEX Driver -
Windows (R) 2000 DDK provider - e846ac230f8d9b
O41 - SISNIC - SiS PCI Fast Ethernet Adapter Driver - C:\WINDOWS\system32\drivers\sisnic.sys - (running)
- SiS PCI Fast Ethernet Adapter Driver - SiS Corporation - 8204c49cde112f7b9c2f1a
O41 - sisperf - SiS Filter Driver - C:\WINDOWS\system32\drivers\sisperf.sys - (running) - SiS Filter
Driver - Silicon Integrated Systems Corp. - 596d4abd344dd
O41 - smwdm - SoundMAX Integrated Digital Audio&&- C:\WINDOWS\system32\drivers\smwdm.sys - (running) -
SoundMAX Integrated Digital Audio&&- Analog Devices, Inc. - 3c8c1ce79a24ec688f1c4646
O41 - EagleNT - EagleNT - C:\WINDOWS\system32\drivers\EagleNT.sys - (not running) -&&-&&-
O41 - NPF - NPF - C:\windows\system32\drivers\npf.sys - (not running) -&&-&&-
=======================================
360Safe.exe=3.5.2.1005
AntiAdwa.dll=3.5.1.1001
AntiEng.dll=3.5.2.1002
AntiActi.dll=2.0.0.3000
CleanHis.dll=3.0.2.1000
safelive.exe=1.0.0.2007
live.dll=1.0.1.1018
=======================================
操作历史报告:
----------清理恶评及系统插件历史----------
查杀恶意软件 - romdrivers下载器 - 危险 - C:\PROGRA~1\INTERN~1\msvcrt.dll
查杀恶意软件 - romdrivers下载器 - 危险 -
查杀恶意软件 - romdrivers下载器 - 危险 - C:\PROGRA~1\INTERN~1\msvcrt.dll
查杀恶意软件 - romdrivers下载器 - 危险 -
插件管理 - romdrivers下载器 -
清理恶评插件 - WinDHCPsvc - C:\windows\system32\windhcp.ocx
清理恶评插件 - cpush广告软件 - C:\Program Files\Common Files\CPUSH
清理恶评插件 - WinDHCPsvc - C:\windows\system32\windhcp.ocx
清理恶评插件 - acpidisk驱动 - C:\windows\system32\drivers\acpidisk.sys
清理恶评插件 - PCTools -
清理恶评插件 - WinDHCPsvc - C:\windows\system32\windhcp.ocx
清理恶评插件 - acpidisk驱动 - C:\windows\system32\drivers\acpidisk.sys
清理恶评插件 - PCTools -
----------全面诊断修复历史----------
O4 - 未知 - MSDWG32 - LYLoadbr.exe
O4 - 未知 - MSDCG32& &&&- LYLeador.exe
O4 - 未知 - MSDOG32 - LYLoador.exe
O4 - 未知 - MSDSG32 - LYLoadar.exe
O4 - 未知 - MSDMG32 - LYLoadmr.exe
O4 - 未知 - MSDHG32 - LYLoadhr.exe
O4 - 未知 - MSDQG32 - LYLoadqr.exe
O8 - 未知 - 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - 未知 - 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - 未知 - 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - 未知 - 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O23 - 未知 - WinDHCPsvc -
O20 - 未知 - 自启动项AppInit_DLLs - dhbpri.dll
O20 - 未知 - 自启动项AppInit_DLLs - jzgpri.dll
=======================================
头像被屏蔽
WinDHCPsvc清理给你参考一下。。。。。。。。。。。
病毒/木马名称:WinDHCPsvc downloader木马
病毒/木马进程:WinDHCPsvc.exe
服务名称:WinDHCPsvc
显示名称:Windows DHCP Service
文件位置:C:\WINDOWS\WINDHCP.OCX
服务参数:C:\WINDOWS\SYSTEM32\RUNDLL32.EXE WINDHCP.OCX,START
文件说明:(风险级别高)
中毒症状:
1、后台自动下载、伪装系统程序、强制安装、无法彻底删除。360安全卫士、木马杀客、等反流氓软件可以找到的WinDHCPsvc&&downloader木马,但是无法清除。而且到注册表里手动也无法删除WinDHCPsvc&&downloader木马。2、没有启动IE的情况下, 不停的运行多个iexplore.exe还是大写的,iexplore.exe文件地址属于XP自带的IE没错。所以一般杀毒软件全部检测为正常。其他系统进程正常,也没多出异常的进程。
但是细心的人就会发现服务中多出了:windows DHCP service &C:\WINDOWS\system32\rundll32.exe windhcp.ocx,start&&Microsoft Corporation&
“恶意软件清理”会提示检测到“WinDHCPsvc”,指向HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WinDHCPsvc& &&&但是无法清除;
360safe的服务项里面会有服务windows DHCP service ,虽然你选中并点击“修复选中项”,重新扫描之后还是安然无恙。
病毒/木马专杀分析:
是病毒.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root键项键值都有权限保护,要将“完全访问”添加入权限再可删除。
windhcpsvc 木马专杀方法(查杀方法):
1.杀毒前关闭系统还原:右键 我的电脑-属性-系统还原-在所有驱动器上关闭系统还原 打勾即可。& &
2.清除IE的临时文件:打开IE 点工具--Internet选项-Internet临时文件-点“删除文件”按钮-将 删除所有脱机内容 打勾-点确定删除。
3.用强制删除工具 PowerRMV 删除以下两个文件,分别填入下面的文件(包括完整的路径) ,勾选“抑止杀灭对象再次生成”,点杀灭 ,有找不到提示的请忽略:
& && && && && && && &c:\windows\system32\twunk32.exe
& && && && && && && &c:\Program Files\Tencent\QQ2006\TIMPlatfrom.exe
这个是你QQ的安装目录,不一定是这个目录,反正就是的QQ目录里面,找到这个文件TIMPlatfrom.exe 。这里请注意了: 我们正常的文件是 TIMPlatform.exe而不是 TIMPlatfrom.exe
2.删除注册表[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]下面的load键。
3.删除注册表[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDHCPsvc
4.定位到[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WinDHCPsvc]将“完全访问”添加入LEGACY_WinDHCPsvc的访问权限,删除LEGACY_WinDHCPsvc项。
提示:以上操作尽量在安全模式下删除。
arthor_pan
啊!谢谢高手指导!进行中
arthor_pan
不行啊!在系统中找不到所说的两个文件,在注册表中也没有所提到的键值
首先建议你杀下毒··中了木马的话我推荐用EWIDO查杀···
呵呵···记得在安全模式下杀哦···
然后呢···用360安全卫士修复下IE··
arthor_pan
我早就在安全模式下已杀毒,用360进行检测说已没有木马,卡巴也没查出毒.但是只要一连上网络,za就报告拦截间谍网址不知道什么原因啊!
zjwllilinjie
安装AVG后,查一下马.试一下.
Copyright & KaFan & All Rights Reserved.
Powered by Discuz! X3.1( 苏ICP备号 ) GMT+8,

我要回帖

更多关于 syssp木马有哪些影响 的文章

 

随机推荐